Services

Build it, learn it, or hand it over.

Three service lines that fit together in any combination. Most people start with a build, take the education that comes with it, and decide later how much of the ongoing care they want to keep.

01 — Education

Learn to run it yourself

Worked through on your own hardware, at your pace, with notes you keep. Take a single topic to unblock yourself, or the lot as a course. Every subject below is a session you can book.

Setting up a home server

What the hardware actually needs to do, choosing between a hypervisor like Proxmox VE and a plain Linux box, laying out storage and filesystems, and getting your first service running end to end.

Managing updates

Container images, host packages and app-level schema migrations all move at different speeds. Which ones are safe to automate, which need a human and a snapshot first, how to read a changelog for breaking changes, and how to roll back when one bites.

Managing uptime

Health checks and alerting so you hear about a problem before your family does, disk monitoring (SMART, ZFS scrubs), a UPS sized for a clean shutdown, and an honest look at what uptime a machine in a closet can realistically hit.

Exposing resources

Getting to your services from outside your local network: port forwarding, dynamic DNS, what to do when your ISP puts you behind CGNAT, and tunnel options that work without opening anything at all.

VPN vs. internet exposure

The central trade-off. A VPN like Tailscale means nothing is on the public internet and the attack surface is near zero, but every device needs a client. Sharing your shiny new services with less technical community can be a challenging sell. Public exposure works in any browser and shares effortlessly, but you now own patching, TLS, authentication and abuse handling. Most communities want a VPN for admin and one or two carefully exposed services for everyone else.

Security for exposed services

The layered version: one open port behind a reverse proxy, automatic TLS, strong authentication or single sign-on in front of anything sensitive, CrowdSec or fail2ban on the edge, unprivileged containers, a separate VLAN for the server, and a patch routine you'll actually keep to.

Using a reverse proxy

Why one entry point beats a dozen port numbers: clean subdomains, certificates that renew themselves, per-service access rules, and a single place to look when something returns the wrong page. We like Caddy because its configuration fits on a postcard and reloads immediately.

Rented VPS vs. physical home server

A home box costs electricity, noise, and your own hardware risk, but the data never leaves your building and storage is as cheap as a drive. A VPS costs rent forever and lives on someone else's disks in someone else's jurisdiction, but it has a static IP, real upload bandwidth, and no hardware to replace. There's no wrong answer, just what you're willing to pay for and manage.

Managing a domain

Picking a registrar that won't hold your name hostage, the DNS records that matter, wildcard subdomains, DNS-01 challenges for certificates on services you never expose, and split-horizon DNS so the same address works on and off your network.

Backups that restore

The 3-2-1 rule applied to your real-life data. Why a RAID array and a snapshot are not backups, how to pick between Borg, Restic and Proxmox Backup Server, encrypting an offsite copy so the offsite host can't read it, and running a restore drill on a schedule so you know it works.

FORMAT

Remote sessions

Screen share, your machine, my voice. Recorded if you want it, with a written summary and the exact commands afterwards. Billed hourly. See pricing.

FORMAT

In person

For the physical half that includes building the machine, running cable, fitting drives, seeing the rack. Available in northern Colorado and the Denver area.

02 — Server management

Let us keep it running

Self-hosting fun to set up but can be a pain to manage. This is the part most people want off their plate: keeping the thing patched, backed up, and answering when your community needs your services.

UPDATES

Updates and conflict resolution

Snapshot first, update, verify, and roll back if a release goes sideways. Breaking changes read in advance, database migrations run deliberately, and dependency conflicts untangled rather than left to sit on an old version forever.

BACKUPS

Backup custody

An encrypted offsite copy of what matters, held on my storage, so a fire or a theft doesn't take the family photos with it. Encrypted with your key before it leaves your building. we'll hold the bytes, not the content. Periodic restore tests, quoted per dataset.

SUPPORT

Helpdesk and remote hands

Something's down, someone can't log in, a drive is making a noise. Reach us directly and we'll get onto the box remotely and fix it. Billed hourly, with no minimum retainer.

SCOUTING

Worth-a-look reports

The self-hosted world moves fast and most of it isn't worth your attention. We follow it so you don't have to, and tell you when something genuinely cool crosses my path or software you're using stops being maintained.

Migrations. Moving off a cloud service, or from one self-hosted app to another (Plex to Jellyfin, Google Photos to Immich, an old NAS to a new one) is quoted per job, based on the apps involved and how much data has to move. Data integrity is checked before the old copy is touched, and nothing is deleted until you say so.
03 — Hardware

Get the right machine, for the right money

The most common mistake in this hobby is buying too much machine. The second is buying a loud one. We spec to the job you described, not to the build someone posted online.

Recommendations

A written spec sized to your services, your storage, and how many people will stream at once. Free with any build, or as a paid consult on its own.

Sourcing

Refurbished mini PCs, off-lease small-form-factor desktops and used drives, or even full server racks if you're feeling enthusiastic. Priced and vetted. Often half the cost of new for the same capability.

Custom builds

Assembled and imaged for the unusual cases: lots of drive bays, a GPU for transcoding, a fanless box for a living room, or ECC memory for a ZFS pool.

Plug-and-play boxes

A finished homelab in a box: hypervisor, dashboard and your chosen services pre-installed. Plug in power and ethernet, open the dashboard, done.

Already own something? Bring it. An old desktop, a gaming PC you replaced, or a NAS with spare capacity is usually enough for photos, media and files. Bring-your-own-hardware setups are billed at a flat rate based on the services installed, and we'll tell you up front if the machine isn't up to what you're asking of it.
Next step

Let's find out what you actually need

A free 30-minute call. We talk about what you want off the cloud, what hardware you have, and what it would take. No obligation, and if the honest answer is "you don't need us for this," you'll get that answer.